E-Rickshaw BMS Cybersecurity Vulnerability: CERT-In’s Bluetooth Warning to Fleets

Electric three-wheelers and e-rickshaws on an Indian street, the fleet segment exposed to the e-rickshaw BMS cybersecurity vulnerability CERT-In flagged

💡 E-Rickshaw BMS Cybersecurity Vulnerability: Key Highlights

  • CERT-In confirmed a real risk: unauthorised users can use a publicly available app to abruptly cut power to a moving e-rickshaw via a Bluetooth flaw in its Battery Management System (BMS).
  • Root cause: BMS Bluetooth modules in low-cost e-rickshaws ship with default or no pairing credentials — anyone in range with the matching app can connect.
  • Government has acted: CERT-In referred the offending apps to MeitY for app-store removal; the Ministry of Heavy Industries (MHI) issued a Bluetooth-BMS advisory to SIAM, ACMA, and testing agencies.
  • No dedicated e-rickshaw cybersecurity rule exists yet — AIS 156 and AIS 038 Rev. 2 cover battery and powertrain safety, not wireless-pairing security.
  • Broader rules are already drafted: MoRTH’s 17 June 2026 notification (G.S.R. 503(E)) proposes AIS-189/AIS-190 cybersecurity approval for category L, M and N vehicles.
  • This lands on the fastest-growing fleet segment: EVs are ~42% of India’s three-wheeler sales, and fleet-run three-wheelers are growing at roughly 30% CAGR — faster than individual ownership.

If you run e-rickshaws or shared three-wheelers, here is an uncomfortable fact: until recently, a stranger with a free, publicly listed app could remotely cut power to a moving vehicle in your fleet. That is the substance of the e-rickshaw BMS cybersecurity vulnerability that CERT-In (the Indian Computer Emergency Response Team) has now confirmed — traced to an unsecured Bluetooth pairing on the Battery Management System (BMS) chip embedded in low-cost e-rickshaw battery packs.

This is not evidence that electric three-wheelers are broadly unsafe — it is a component-level security gap in cheap BMS hardware that is now being addressed through app takedowns, an industry advisory, and rules already in the drafting pipeline. But for fleet operators running e-rickshaws and last-mile three-wheelers at scale, it is also a preview of a compliance dimension — vehicle cybersecurity — that barely existed in India’s EV regulation eighteen months ago and is now moving fast. Here is what CERT-In found, what the government has done about it, where the rules actually stand today, and what it means for how you should be buying and auditing BMS hardware.

What CERT-In Found: A Free App Can Kill Power to a Moving E-Rickshaw

CERT-In received safety-concern reports describing exactly this scenario: unauthorised individuals abruptly powering off moving e-rickshaws using a publicly available BMS mobile app. Tracing the reports, CERT-In found the root cause sitting inside the Bluetooth module of the BMS chip embedded in the battery pack — hardware commonly fitted in low-cost e-rickshaws sold across India. That module ships with default or, in some cases, no credentials at all, which means anyone with the matching app and Bluetooth range can connect to it, change settings, or cut the battery’s discharge outright.

Cutting a battery’s discharge is not a data-privacy inconvenience — it is a sudden, uncommanded shutdown of a moving vehicle’s power. For a three-wheeler carrying passengers or cargo in traffic, that is a genuine road-safety hazard, which is exactly why CERT-In escalated it rather than treating it as a minor software bug.

Why Cheap BMS Hardware Has No Real Security

The BMS apps at the centre of this story exist for a legitimate reason: they let an owner check charge percentage, cell health, and diagnostics from a phone. But on the least expensive BMS boards supplied into India’s e-rickshaw segment, that convenience was built with generic or absent pairing credentials — not per-device authentication. In practice, that means the same app can often pair with any unit running the same firmware, not just the buyer’s own vehicle. It is a classic cost-down security trade-off: the app was built to be easy to connect to, not hard to break into.

The Government’s Response So Far

The response chain here moved faster than India’s EV cybersecurity rulebook itself — because this was treated as an active safety risk, not a policy debate.

CERT-In’s App Takedown Referral to MeitY

CERT-In identified the specific apps enabling the unauthorised shutdowns and referred them to the Ministry of Electronics and Information Technology (MeitY) for removal from app stores. Separately, in a related written reply, MeitY confirmed that takedown orders for the identified apps were issued in early July 2026 — the app-store removal is already underway rather than merely proposed.

MHI’s Advisory to SIAM and ACMA

The Ministry of Heavy Industries (MHI) has issued an advisory on the Bluetooth BMS vulnerability directly to the Society of Indian Automobile Manufacturers (SIAM) and the Automotive Component Manufacturers Association (ACMA), as well as to vehicle testing agencies. That puts the fix squarely on OEMs and BMS component suppliers — credential-hardening and firmware updates, not a one-time app removal, is the durable resolution.

Where India’s EV Cybersecurity Rules Actually Stand

The uncomfortable regulatory answer, per the Ministry of Road Transport and Highways (MoRTH): no dedicated cybersecurity regulation currently exists specifically for e-rickshaws (L-category vehicles) or e-karts. That gap is precisely why a Bluetooth pairing flaw like this one could ship, unnoticed, on thousands of vehicles.

AIS 156 and AIS 038 Cover Safety, Not Cybersecurity

L-category EVs, including e-rickshaws, must already meet AIS 156 (Battery Safety Requirements) and AIS 038 Rev. 2 (Electric Power Train Safety) — and every EV manufacturer or importer must submit prototypes for Type Approval Certification under Rule 126 of the Central Motor Vehicle Rules (CMVR), 1989. But these standards test thermal runaway, electrical isolation, and mechanical safety. None of them test whether a BMS’s Bluetooth pairing can be hijacked by a stranger’s phone — that is simply a different failure mode than the one AIS 156/038 was written to catch.

The Draft AIS-189/190 Rules Closing the Gap

MoRTH published draft rules on 17 June 2026 (G.S.R. 503(E)) proposing mandatory cybersecurity approval for category L, M and N vehicles under AIS-189 (Cyber Security Management System) and AIS-190 (Software Update Management System) — standards modelled on the international UNECE R155/R156 and ISO/SAE 21434 frameworks. The proposed rollout is phased by risk: vehicles with Level 3+ automated-driving features comply first, from October 2026, with broader categories following through 2028. In other words, the rules that would eventually force BMS suppliers to harden Bluetooth pairing on e-rickshaws are already in motion — they are just not enforceable yet, and initial enforcement priority is aimed at higher-automation M/N-category vehicles rather than budget three-wheelers.

What It Means for Fleet Operators

This vulnerability lands squarely on the segment fleets are scaling into fastest. Electric variants now account for roughly 42% of all three-wheeler sales in India, and while individual owner-drivers still control the bulk of the installed base, fleet-operated three-wheelers are growing at close to 30% CAGR — the fastest-growing ownership model in the category. If your fleet is expanding into e-rickshaws or shared three-wheelers, this is not someone else’s compliance problem.

Audit Your BMS Suppliers Now

Start with an inventory: which e-rickshaws and which BMS suppliers are actually in your fleet? Ask each vendor directly whether their BMS firmware uses unique per-device pairing credentials or app-level authentication, and whether a patch or firmware update addressing this specific advisory is available. Don’t assume “budget hardware” and “insecure hardware” are always the same SKU — some suppliers will have already hardened credentials; others won’t have, and won’t volunteer that fact unprompted.

Weight Vendor Security in Procurement, Not Just Price

Going forward, treat AIS-156/AIS-038 compliance plus a vendor’s demonstrated security practice as procurement criteria alongside sticker price — not after it, once. Fleet-wide vehicle management that tracks battery health and state-of-charge across every unit gives you the visibility to catch an anomalous, uncommanded shutdown pattern before it becomes a road incident, rather than after a driver complaint. Layering in fleet alerts and monitoring means a vehicle unexpectedly going offline or losing power mid-route triggers an immediate flag to ops — not a mystery a driver has to explain after the fact. This is exactly the kind of cross-vendor, fleet-wide risk visibility a fleet management platform like YoMobility is built to give operators, regardless of which BMS supplier sits inside any individual vehicle.

Frequently Asked Questions

What exactly is the e-rickshaw BMS cybersecurity vulnerability CERT-In flagged?

It’s a Bluetooth pairing flaw in the Battery Management System (BMS) chip used in low-cost e-rickshaw battery packs. Because the BMS’s Bluetooth module ships with default or no credentials, a publicly available companion app can connect to it without the vehicle owner’s authorisation and modify settings or cut battery discharge.

Can this actually stop a moving e-rickshaw?

Yes — cutting the battery’s discharge causes a sudden, uncommanded shutdown of the vehicle’s power while it is in motion, which is why CERT-In treated the reports as a genuine road-safety issue rather than a minor app bug.

Which e-rickshaws are affected?

The advisory points to low-cost e-rickshaws using BMS chips with unsecured Bluetooth pairing — a common, but not universal, hardware choice across budget three-wheeler battery packs. It is not a defect specific to one OEM; it is a component-level weakness found across multiple low-cost BMS suppliers.

Is there a fix available yet?

CERT-In has referred the identified apps to MeitY, which confirmed takedown orders were issued in early July 2026. The Ministry of Heavy Industries has separately advised SIAM, ACMA, and testing agencies on the underlying Bluetooth BMS issue — the durable fix (credential-hardening and firmware updates) sits with individual BMS suppliers and OEMs.

Are there cybersecurity rules for e-rickshaws in India?

Not yet, specifically. Existing standards (AIS 156, AIS 038 Rev. 2) cover battery and powertrain safety, not wireless-security. MoRTH’s draft rules (G.S.R. 503(E), 17 June 2026) would introduce cybersecurity approval requirements under AIS-189/AIS-190 for category L, M and N vehicles, but they are still in draft and phased toward higher-automation vehicles first.

What should fleet operators do right now?

Audit which e-rickshaws and BMS suppliers are in your fleet, ask vendors directly about credential-hardening and firmware fixes, and start weighting vendor security practice — alongside AIS-156/AIS-038 compliance — in procurement decisions rather than choosing on price alone.

Source: Cybersecurity Vulnerabilities in E-Rickshaw BMS and Role of Certification Agencies — Ministry of Heavy Industries, written reply in the Lok Sabha, 21 Jul 2026 (PRID 2287127).

Manage Your Fleet’s Vehicle & Battery Risk Today

Don’t wait for the next vendor advisory to find out which e-rickshaws or BMS suppliers are on your books. YoMobility gives fleet operators one dashboard for vehicle health, battery status, and anomaly alerts — across every vehicle and every vendor in the fleet.

Book a Free Demo
Scroll to Top